COMMERCIAL AND COMPANY LAW

Corporate Compliance

Compliance is achieved not with a set of policies sitting in a folder but with an operation that knows where data enters the company and where it flows. On the KVKK side, most obligations are a matter of process, not documents: the inventory is kept up to date, the texts describe the actual processing activity, and supplier contracts are tied into the same arrangement.

KVKK compliance begins with drawing up the personal data processing inventory; privacy notices, explicit consent texts and the retention and destruction policy are prepared on the basis of this inventory. The obligation to inform (Article 10 of Law No. 6698) applies subject to the exceptions in Article 28; explicit consent comes into play only where none of the other processing conditions in the Law is present, and it cannot be made a precondition of the service. VERBİS registration is assessed against the Board’s current exemptions, including separate rules for controllers whose main activity is processing special categories of data. Data-security obligations should be reflected in supplier contracts; a separately titled addendum is not invariably mandatory.

What we do in this area

Corporate compliance is the work of turning what legislation expects of a company into its daily operation. The weight of this heading at our office is the compliance process under the Personal Data Protection Law No. 6698 (KVKK): drawing up the personal data processing inventory, preparing privacy notices and explicit consent texts, VERBİS registration, writing the retention and destruction policy and internal directives, and attaching data processing addenda to supplier contracts. Internal rules on disciplinary and ethics procedures are also handled within this scope.

The work proceeds along the advisory axis rather than litigation and is usually part of a corporate legal advisory relationship. For contract structuring in general, see commercial contracts; for the company law side, see commercial and company law.

KVKK compliance is a matter of process, not documents

The picture most frequently encountered in practice is a privacy notice taken from the internet being placed on the website and compliance being assumed complete. What the Law requires, however, is that the company knows which data it processes, for what purpose and on which legal basis, and can document this. That is why the work starts at the same place in every company: the data inventory. Which unit collects which data, where it stores it, to whom it transfers it, when it deletes it; every text written before this table exists rests on assumption.

Once the inventory is drawn up, each processing activity is matched with the processing conditions in Articles 5 and 6 of the Law. Explicit consent is only one of these conditions; where another processing condition exists, asking for explicit consent is unnecessary and leaves the company in a difficult position if the consent is withdrawn. VERBİS registration depends on the applicable Board exemptions. For controllers whose main activity is not processing special categories of data, the general size exemption requires both no more than fifty employees annually and an annual balance sheet no greater than TRY 100 million; exceeding either threshold removes that exemption. Under Decision 2025/1572, controllers whose main activity is processing special categories of data may also qualify for an exemption if they have no more than ten employees annually and an annual balance sheet no greater than TRY 10 million. Other exemptions and the applicable calculation rules must also be checked.

The set of documents prepared

Document Function
Personal data processing inventory The basis of compliance; the VERBİS notification and all texts are fed from it
Privacy notices Information under Article 10 KVKK, subject to Article 28 exceptions
Explicit consent texts Only for activities where no other processing condition exists
Retention and destruction policy Sets how long data is kept and how it is destroyed
Special categories of data policy Additional measures for sensitive categories such as health data
Disciplinary and ethics directive The framework for the internal reporting, investigation and sanction process
Data processing addendum The contract annex signed with a supplier that processes data on the company's behalf

Supplier contracts and data processing addenda

The data security obligation (Article 12 KVKK) is not limited to the company's own systems. A supplier providing payroll, server hosting, courier or call centre services becomes a data processor when it processes data on the company's behalf and is liable for security jointly with the data controller. This relationship is documented through appropriate contractual provisions, which may be in the main contract or an addendum: the subject and duration of the processing, the security measures to be taken, the use of sub-processors, the right of audit and the return or destruction of the data when the contract ends are regulated in this addendum. In relationships involving transfers abroad, the transfer regime in Article 9 of the Law is assessed separately; this regime was amended in 2024 by Law No. 7499 and a standard contract procedure was introduced.

Disciplinary and ethics procedures

Internal directives are not written for data protection alone. The disciplinary procedure, the ethics reporting channel and the internal investigation procedure determine both the lawfulness of the measure applied to the employee and the company's ability to prove its case in a possible termination. A sanction imposed without taking the employee's defence turns against the company in a later reinstatement action. Because of this link, internal directives are structured together with the labour law side.

The moment of breach or request: the plan is written in advance

What to do when a data breach occurs is not decided on the day. Under Board decisions, notification of the breach to the Authority and to the affected persons is subject to short time limits; who will decide, how records will be kept and how the notification will be made are written in advance into a response plan. Requests from data subjects must also be answered within thirty days at the latest (Article 13 KVKK); who will receive the request and how the response will be prepared are regulated in the internal directive.

This is general information; obligations vary according to the company's scale and the data it processes.

The page where we describe the process in detail: Our working process.

FREQUENTLY ASKED

What people ask about this area

Is KVKK compliance a one-off project?
No. Preparing the texts is the start of the work; when new software is purchased, work begins with a new supplier or a new category of data is processed, the inventory and the texts are updated. For this reason, compliance work runs in most companies as an ongoing advisory relationship.
Am I required to register with VERBİS?
VERBİS registration depends on the applicable Board exemptions. For controllers whose main activity is not processing special categories of data, the general size exemption requires both no more than fifty employees annually and an annual balance sheet no greater than TRY 100 million; exceeding either threshold removes that exemption. Under Decision 2025/1572, controllers whose main activity is processing special categories of data may also qualify for an exemption if they have no more than ten employees annually and an annual balance sheet no greater than TRY 10 million. Other exemptions and the applicable calculation rules must also be checked. Exemption from registration does not remove the other applicable KVKK obligations.
Are a privacy notice and an explicit consent form the same thing?
No. The privacy notice fulfils the information obligation under Article 10 KVKK, subject to Article 28 exceptions, and does not depend on consent. Explicit consent is a distinct processing condition used where appropriate and must be freely given, specific and informed. Where both are needed, informing the individual and obtaining consent must be separate processes; an acknowledgement that a notice was read does not itself constitute valid consent.
Can we not just use ready-made texts we found on the internet?
A ready-made text describes another company's data processing activity. If the privacy notice lists data that is not actually processed, or makes no mention of a transfer that actually takes place, the obligation has not been fulfilled even though the text exists. In a Board investigation, what protects the company is not the existence of the text but its consistency with the inventory and the actual operation.

If your question is not hereContact

IMPORTANT NOTICE

This page is general information only and does not constitute legal advice. Every file is assessed on its own documents, dates and parties; the general explanations here cannot be applied directly to your own situation. Prepared in line with the Union of Turkish Bar Associations’ advertising restrictions. This English text is a courtesy translation prepared by the firm; in case of any discrepancy the Turkish text prevails.

Write on WhatsApp